Security & Data Ethics

Built for healthcare.
Governed by design.

OutcomesAI handles clinical, operational, and financial data under HIPAA—with an ethics posture that is structural, not aspirational. Each element is explainable in one sentence.

The compliance foundation

HIPAA with BAAs across the stack

Business Associate Agreements are in place across the cloud infrastructure—including the AI model provider.

PHI stays in the covered environment

AI models run through AWS Bedrock inside the covered environment. Clinical data never leaves for a public AI service.

Encrypted everywhere

All data is encrypted in transit and at rest with AES-256 encryption.

Isolated by tenant

Row-level security enforces strict practice-level data isolation. Every access is authenticated.

No public database access

The production database is not publicly reachable; administrative access requires an audited bastion session.

Auditable by construction

Scores and configurations are append-only and versioned—any past decision can be reconstructed exactly as it was made.

How the clinical AI is governed

Trust is earned structurally—by being groundable, reproducible, and governed—rather than asked for.

Minimum necessary output

The AI extracts only codes from a controlled clinical vocabulary plus the specific verbatim sentence supporting each finding—never free-form narrative about the patient.

No fabrication by design

Uncertainty is representable: vague durations keep the clinician’s original words, and severity is never inferred from questionnaire scores—the system cannot silently invent clinical facts.

Payer-blind scoring

Insurance coverage is excluded from candidacy scoring and from every display panel by ratified principle—a patient’s clinical priority is never shaped by their coverage.

Human governance

No model version or scoring weight reaches patient-facing workflows without clinician ratification—new versions run in shadow beside the live system until clinicians approve them against real cases.

Questions about security or compliance?

We’re happy to walk your security or compliance team through the architecture.